CKS Minimize Microservice Vulnerabilities Practice Question
Which TWO of the following are valid Pod Security Context settings to harden a container? (Select 2)
⚠ Common exam trap
A common misconception is that setting `runAsUser: 0` is a hardening measure because it 'specifies a user,' when in fact it sets the container to run as root, the most dangerous user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsNonRoot: true
Setting `runAsNonRoot: true` in the Pod Security Context forces the container to run with a user ID (UID) other than 0 (root). This is a fundamental hardening measure that prevents an attacker who gains code execution inside the container from having root privileges, thereby limiting the blast radius of a compromise. It is a recommended practice in the CIS Benchmark for Kubernetes and directly addresses the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
privileged: true
Why it's wrong here
Setting `privileged: true` runs the container in privileged mode, granting it all capabilities and disabling most security mechanisms like seccomp, AppArmor, and SELinux. This is equivalent to running the process as root on the host, making it a serious security risk. It is not a security hardening measure but rather a way to bypass security.
- ✗
runAsUser: 0
Why it's wrong here
Setting `runAsUser: 0` explicitly runs the container process as the root user (UID 0), which escalates privileges within the container. This is risky because root in the container may leverage capabilities to access host resources if kernel protections are insufficient. It is not a security context setting that enhances security; instead, it is a misconfiguration that should be avoided.
- ✓
runAsNonRoot: true
Why this is correct
Setting `runAsNonRoot: true` enforces that the container process runs as a non-root user by rejecting the image's default user if it is root. This prevents the container from gaining root privileges inside the container, reducing the attack surface. It is a valuable security context setting recommended in Pod Security Standards.
- ✓
readOnlyRootFilesystem: true
Why this is correct
Setting `readOnlyRootFilesystem: true` mounts the container's root filesystem as read-only, preventing writes to the filesystem and blocking malicious modifications or persistence. Applications must write to ephemeral volumes or external storage if needed. This is a valid security context setting that enhances container immutability and limits the impact of a compromised process.
- ✗
allowPrivilegeEscalation: true
Why it's wrong here
Setting `allowPrivilegeEscalation: true` permits a container process to elevate its privileges beyond those of its parent process, such as through setuid-executable gains. This can enable an attacker to achieve root access even if the container runs as a non-root user. The secure default is to set it to false, so this setting is not considered a valid security control.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.